Sceawere

Vulnerability Detail

CVE-2026-89178UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WeenyGenius Origin Validation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
2h ago
Vendor
Howyar
Product
WeenyGenius
Attack Type
CWE-940 Improper Verification of Source of a Communication Channel
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-11T08:16:48.947Z",
  "pubdate": "2026-09-11T08:16:48.947Z",
  "executiveSummary": "WeenyGenius by Howyar Technologies contains a critical Origin Validation Error vulnerability that allows unauthenticated, network-adjacent attackers to spoof legitimate teacher workstation communications.\nThe vulnerability stems from the system's failure to cryptographically verify or authenticate broadcast management packets sent across the local network.\nAn attacker can exploit this flaw to perform unauthorized command execution or system redirection by masquerading as the primary management server.\nThe scope of this vulnerability is limited to the local broadcast domain, requiring the attacker to be positioned on the same network segment as the target student workstations.\nSuccessful exploitation allows an adversary to force student computers to initiate unauthorized connections to a malicious host, effectively hijacking the client-server relationship.\nGiven the nature of lab management systems, this could lead to full workstation compromise, unauthorized software deployment, or surveillance of student activities.\nThe vulnerability represents a significant security risk to educational environments where network segmentation may be insufficient to prevent lateral movement or malicious broadcasts.",
  "technicalDetails": "The vulnerability is classified as an Origin Validation Error occurring within the network communication architecture of the WeenyGenius lab management system.\nThe root cause of the vulnerability is the system's reliance on unauthenticated broadcast protocols for discovery and command signaling. The client-side software components on student workstations are designed to listen for specific broadcast packets originating from the teacher workstation to synchronize tasks and establish management sessions.\nBecause the protocol lacks a secure handshake or verification mechanism for the source of these broadcasts, the application implicitly trusts any packet matching the expected structure. This permits an attacker to forge network datagrams that mimic the legitimate teacher workstation's signaling patterns.\nThe attack flow follows a predictable sequence: First, the attacker performs network reconnaissance to identify the traffic patterns of the WeenyGenius protocol. Second, the attacker crafts a spoofed broadcast packet containing the necessary command flags and identifiers required by the student client.\nUpon receiving the malicious broadcast packet, the student workstation's background agent evaluates the packet as valid due to the lack of source origin validation. The agent then attempts to resolve and connect to the attacker-controlled IP address or workstation, believing it to be the authorized teacher console.\nOnce the connection is established, the attacker can leverage the trust relationship between the student workstation and the management service to push malicious configurations, intercept sensitive data, or force the execution of arbitrary remote commands with the privileges assigned to the WeenyGenius service account.\nThis vulnerability is particularly impactful because it bypasses the need for existing credentials or established session tokens. The requirement for local network access remains the primary barrier, but in typical computer lab environments, this level of exposure is often considered standard, rendering the impact severe.\nThe behavior of the payload is strictly defined by the packet structure that triggers the connection attempt; it forces the client into a state where it initiates an outbound connection, bypassing potential ingress firewall rules on the student machine."
}
CVE-2026-89178: WeenyGenius Origin Validation Vulnerability (HIGH Severity, CVSS: 8.8) | Sceawere